Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Get fresh and trustworthy IOCs on emerging threats for deeper investigations
Kali365 activity targeting US organizations uncovered in ANY.RUN’s Threat Intelligence Lookup

The results show Kali365 activity across manufacturing, technology, healthcare, government, consulting, and MSSPs. This gives defenders a clearer view of where the campaign is active and which domains, URLs, and infrastructure may be connected to it.

Threat Intelligence Reports add a broader layer of preparation. These reports are manually compiled by ANY.RUN analysts and focus on active malware and phishing campaigns, including APTs and cybercriminal groups.

TI reports created by ANY.RUN analysts for deeper investigations

Each report includes investigation findings and TI Lookup queries that teams can apply to threat hunting, detection reviews, and incident enrichment. This helps SOC teams track emerging attack patterns earlier and prepare before similar activity reaches their environment.

Shut Down Token Abuse Before It Reaches the Business

Kali365 puts pressure on a part of the security stack many organizations still treat as trusted by default: cloud authentication.

The CISO challenge is to ensure the SOC can recognize when a legitimate login flow has been manipulated, trace the activity back to its source, and contain access before email, files, or business systems are affected.

Organizations using ANY.RUN have reported:

  • 94% faster threat triage, helping critical incidents move to action before they are delayed by alert backlogs.
  • Up to 21 minutes less MTTR per case, reducing the window in which attackers can expand access or misuse trusted accounts.
  • Up to 20% lower Tier 1 workload, creating more investigation capacity without immediately adding headcount.
  • 30% fewer Tier 1-to-Tier 2 escalations, allowing senior analysts to focus on complex incidents and higher-risk decisions.

These gains lower response costs, improve the use of existing SOC resources, and shorten the window for token abuse to escalate into fraud, data exposure, or operational disruption.

source: TheHackerNews